govcon.forum

Cybersecurity Maturity Model Certification (CMMC)

Also called: CMMC, CMMC 2.0, CMMC level 1, CMMC level 2, NIST SP 800-171, NIST 800-171, SPRS score, CUI

CMMC is the Department of Defense program that verifies a contractor protects federal contract information and controlled unclassified information, at Level 1 by annual self-assessment, Level 2 against NIST SP 800-171 by self-assessment or third-party assessment, and Level 3 by government assessment.

The program rule is 32 CFR Part 170 and the contract clause is DFARS 252.204-7021, phased into DoD solicitations from late 2025. It sits on top of DFARS 252.204-7012, which already requires contractors handling controlled unclassified information to implement NIST SP 800-171, and DFARS 252.204-7019 and 7020, which require a self-assessment score posted in the Supplier Performance Risk System (SPRS). The solicitation states the required level; a firm without the required certification or self-assessment on file is ineligible for award.

What to check: whether you will handle CUI (Level 2) or only federal contract information (Level 1), the scope of the systems that touch that data, whether the assessment can be self-attested or must be done by a certified third-party assessment organization, and the flow-down to your subcontractors. Start with a gap assessment against NIST SP 800-171 and a system security plan.

What it is not: required by civilian agencies, which use their own rules, and not needed for pure commercial-off-the-shelf sales.

See also: Defense Federal Acquisition Regulation Supplement (DFARS), DIBBS and DLA, Subcontractor, Section K

Questions that use this term

Search all